Multiple Security Vulnerabilities in IBM Sterling Partner Engagement Manager.
Summary
| CVE | CVE-2025-13882 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-18 15:17:04 UTC |
| Updated | 2026-09-18 18:17:47 UTC |
| Description | IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of interaction frequency. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS: 0.004200000 probability, percentile 0.358650000 (date 2026-09-21)
Problem Types: CWE-799 | CWE-799 CWE-799 Improper Control of Interaction Frequency
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| 3.1 | CNA | CVSS | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | IBM | Sterling Partner Engagement Manager Essentials Edition | affected 6.3.0.0 6.3.0.2 semver | Not specified |
| CNA | IBM | Sterling Partner Engagement Manager Essentials Edition | affected 6.2.4.0 6.2.4.4 semver | Not specified |
| CNA | IBM | Sterling Partner Engagement Manager Standard Edition | affected 6.2.4.0 6.2.4.4 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.ibm.com/support/pages/node/7288365 | [email protected] | www.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
Solutions
CNA: IBM strongly recommends addressing the vulnerability now by upgrading to the remediated version below: Product(s)Affected Version RangeRemediated VersionInstructions / DownloadIBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 – 6.3.0.26.3.0.3Download 6.3.0.3IBM Sterling Partner Engagement Manager Essentials Edition6.2.4.0 – 6.2.4.46.2.4.5Download 6.2.4.5IBM Sterling Partner Engagement Manager Standard Edition6.2.4.0 – 6.2.4.46.2.4.5Download 6.2.4.5